ZeroFox Cyber Intelligence Daily Brief - July 12, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - July 12, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- CISA Releases Advisory on Assessment of US FCEB Organization, Highlighting Necessity of Defense-in-Depth
- Apple Notifications Alert Indian iPhone Users of Possible Pegasus-Like Attack
- Several Macau Government Websites Hacked, Says Chinese State Media
CISA Releases Advisory on Assessment of US FCEB Organization, Highlighting Necessity of Defense-in-Depth
What happened: A new CISA advisory (released in coordination with an assessed Federal Civilian Executive Branch agency) details the CISA red team’s activity and TTPs, associated network defense activity, and lessons learned to provide network defenders recommendations for improving their organization’s defensive cyber posture.
Why it matters: The red team noted that the organization’s perimeter network was not adequately firewalled; there was insufficient network segmentation; insufficient isolation of the organization’s defensive investigative activity; and more. CISA recommends organizations implement the listed recommendations in the report to mitigate these issues.
Apple Notifications Alert Indian iPhone Users of Possible Pegasus-Like Attack
What happened: As a part of its quarterly update process, Apple has reportedly notified users across 98 countries, including prominent journalists and politicians, about a possible “mercenary spyware” attack.
Why it matters: Apple had sent similar warnings to several journalists and politicians in various countries last year. The timing of the attack remains uncertain as Apple issues these alerts quarterly. Some users' iPhones might have been compromised for months before receiving notification. The company previously identified the attackers as "state-sponsored" but now refers to them as mercenary spyware attacks. Pegasus spyware, a product of the Israeli NSO Group, has created significant waves in the political landscape of various countries when investigations alleged the use of the spyware on political entities, journalists, and government officials.
Several Macau Government Websites Hacked, Says Chinese State Media
What happened: Security officials of the Macau Special Administrative Region's government announced that several Macau government websites, including crucial departments like The Office of the Secretary for Security, the Public Security Police Force, the Fire Services Bureau, and the Public Security Forces Affairs Bureau were hacked. The intrusion disrupted services and prompted a criminal investigation by local authorities.
Why it matters: Officials have claimed that the source of the intrusion was overseas. The hacking of critical government websites in Macau is a significant security breach with potential implications for national security. Government websites are frequent targets due to the sensitive information they hold and their role in delivering essential services to the public. Hacking can disrupt operations, leading to service outages, data breaches, and potential loss of public trust. Threat actors could further exploit sensitive information stolen from government websites for various malicious purposes, including identity theft, espionage, or launching more targeted cyberattacks. Meanwhile, the authorities carried out an emergency response in conjunction with telecommunication operators to swiftly restore affected services and ensure operational continuity amidst the cyberattack.
DEEP AND DARK WEB INTELLIGENCE
- XSS user “13334”: On July 11 the untested threat actor "13334" advertised Fortinet VPN access bundle to 50 unnamed separate U.S.-based companies on the predominantly Russian language Dark Web forum XSS. According to 13334, the access bundle is a list of Fortinet VPN entry points with credentials.
VULNERABILITY AND EXPLOIT INTELLIGENCE
- CVE-2024-5910: Palo Alto Networks issued updates to fix five security flaws, including CVE-2024-5910 (CVSS 9.3) that allows attackers to take over admin accounts in the Expedition tool.
- Affected products: Palo Alto Networks Expedition versions < 1.2.92.
Tags: DIB, tlp:green